Impact
This vulnerability occurs in Netty's SmtpResponseDecoder component, where an attacker can send an unbounded multi‑line SMTP response without a terminator. The decoder accumulates the data in the JVM heap, eventually causing an OutOfMemoryError and crashing the application. The result is a denial of service. The weakness maps to CWE‑1035.
Affected Systems
Products impacted are Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, and the Red Hat build of Apache Camel for Spring Boot 4. No specific version numbers are listed, so any release incorporating the affected Netty library may be vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity flaw, and the EPSS score is 0.00325, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. A remote attacker who can act as a malicious or man‑in‑the‑middle SMTP server can craft a response that will trigger the memory leak. The attack requires network access to the SMTP client, making the risk significant for systems exposing SMTP services.
OpenCVE Enrichment